CVE-2019-14900

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
hibernatehibernate_orm
𝑥
< 5.3.18
hibernatehibernate_orm
5.4.0 ≤
𝑥
< 5.4.18
redhatbuild_of_quarkus
-
redhatdecision_manager
7.0
redhatfuse
𝑥
< 7.8.0
redhatjboss_data_grid
7.0.0
redhatjboss_enterprise_application_platform
-
redhatjboss_middleware_text-only_advisories
-
redhatsingle_sign-on
-
quarkusquarkus
𝑥
≤ 1.5.2
redhatjboss_enterprise_application_platform
7.3
redhatjboss_enterprise_application_platform
7.4
redhatjboss_enterprise_application_platform
7.3
redhatjboss_enterprise_application_platform
7.4
redhatjboss_enterprise_application_platform
7.3
redhatjboss_enterprise_application_platform
7.2
redhatjboss_enterprise_application_platform
7.2
redhatjboss_enterprise_application_platform
7.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhibernate3-java
bullseye
3.6.10.Final-11
fixed
sid
3.6.10.Final-12
fixed
trixie
3.6.10.Final-12
fixed
bookworm
3.6.10.Final-12
fixed